
2/16/2017
What this post added
This post details the philosophy and impact of Shopify's Bug Bounty program. It highlights the program's evolution since 2012, its partnership with HackerOne since 2015, and the significant number of fixes and bounties awarded. Specific examples of vulnerabilities like 'Invoice Swap', 'Sneaky Catfish', and 'Remote Code Execution' are provided with technical explanations of the bugs and their resolutions, including the bounty amounts and disclosure timelines. The post emphasizes the program's role in maintaining merchant trust and its educational value.